-
It's not often we get prior warning of worms spreading. But yesterday, German officials warned that we would see a new Sober variant using the attachment names “Word Text.zip” or “registration.zip” and, sure enough, we have Sober.V . Unfortunately, on the same day, we also have...
-
A new worm utilizing the MS05-039 vulnerability has became a major outbreak. More coverage upcoming. Details IRCBot is a fast-spreading worm affecting systems not patched for the MS05-039 vulnerability. Infected machines will reboot frequently, as well as connect to an IRC server and await further instructions...
Posted to
Security Manifest
(Weblog)
by
trafton
on
08-16-2005
Filed under: VIRUSES, SECURITY, Security (Medium), Security (Urgent), Viruses (Medium), Viruses (Urgent), Security (Very Urgent), Viruses (Very Urgent)
-
A new version of the extensive and successful MyDoom worm family has appeared. Fortunately, like many recent variants, this version has got off to a slow start and is unlikely to become a major threat. Details MyDoom.CF was discovered Tuesday, June 28th, 2005. It is a standard MyDoom family member, faking...
-
Sober.L is mass-mailing worm that appeared this morning around 10 AM PST and is believed to be spreading rapidly in Germany, and is beginning to appear in several other countries. The worm, like previous Sober variants, spreads in both English and German email addresses, depending on the language of...
-
Crog (also known by several other names, such as Sumom, Serflog, and Fatso - the last name which is likely to become the media name) is an MSN Messenger worm that appeared today and is spreading quickly, earning Medium risk from some antivirus companies. The worm sends itself to victims via MSN Messenger...
-
Kelvir.B (Kelvir.A at Symantec) is an MSN Messenger worm that appeared yesterday, has now been characterized by Symantec as spreading in the field. The worm arrives as a link to the file cute.pif on a web site on the home.att.net domain. It also downloads a variant of W32/SDBot, a backdoor and open share...
-
MyDoom.BB, or .AX at Symantec, has been upgraded to a medium risk rating and is spreading rather quickly. More information available here: http://securityresponse.symantec.com/avcenter/venc/data/w32.mydoom.ax@mm.html http://vil.mcafeesecurity.com/vil/content/v_131856.htm Extended coverage tomorrow afternoon...
-
We may just now be seeing the first notable outbreak of an MSN Messenger worm. Bropia.G, known by various other letters depending on the antivirus company, is a variant of the slightly successful Bropia family. Like past variants, .G spreads via MSN Messenger to any contact that changes their status...
-
McAfee has gone Medium risk on the latest version of the Sober worm family, Sober.K. Due to illness, my coverage of this worm will be limited. I highly recommend checking out the McAfeeHelp topic here where they will be tracking this developing threat: http://forums.mcafeehelp.com/viewtopic.php?t=40406...
-
PERL.Santy is a worm that utilized the search engine Google in order to search for vulnerable web sites running phpBB software. phpBB 2.0.10 is affected; 2.0.11 is not. Vulnerable web sites will have this at the footer: Powered by phpBB 2.0.10 © 2001 phpBB Group Yet again, F-Secure's weblog did...